APT37__2018__Red_Eyes_Hacking_Group_Report.pdf
ID: 9a3a5ea6-671e-4f7a-8dc1-b816a6af4b4b
STIX ID: report--9a3a5ea6-671e-4f7a-8dc1-b816a6af4b4b
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2018-08-14
Last Modified Date: 2018-08-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AhnLab's report documents a multi-year campaign by the Red Eyes actor (aka APT37/Group 123) targeting North Korea-related individuals and organizations using malicious Hangul/Office documents, mobile messenger lures, and exploitation of vulnerabilities including an Adobe Flash zero-day (CVE-2018-4878) and Hangul EPS; malware families include loaders (DocPrint/Reloader), Reloaderx (system enumeration and downloader), Redoor/DogCall backdoors, and destructive wipers, with numerous IoCs (MD5s, PDB strings, C2 URLs) and evidence suggesting ties to an earlier 2015 campaign (Operation ProgamsByMe).
